Skip to content

Risk Treatment Plan

Purpose. Turns the Risk Assessment Report (ISMS-DOC-06-3) into tracked, owned actions with due dates (ISO/IEC 27001 6.1.3, 8.3). Per the acceptance criteria: ๐Ÿ”ด High (10โ€“25) must be treated; ๐ŸŸก Medium (5โ€“9) is treated where proportionate with the decision documented; ๐ŸŸข Low (1โ€“4) is retained.

1. Scope

All risks in the Risk Assessment Report at or above the treatment threshold. Status is updated in the weekly ISMS sync; the plan is formally reviewed at management review and at least annually. Risk owners approve this plan and accept the residual risks (6.1.3 f/g) โ€” recorded at management review.

2. Treatment actions โ€” ๐Ÿ”ด High risks (must treat)

Ordered by initial risk level. โšก = quick win. All due dates are TODO(owner): set at the 2026-07-24 sync.

Risk Initial Action(s) Action owner Due Status Target residual
R-01 BYOD endpoint loss/malware ๐Ÿ”ด 16 Enforce disk encryption + screen lock + auto-updates on all devices per Device Management Policy; decide MDM tooling (see R-02) TODO(owner) TODO Open ๐ŸŸก 8
R-21 Product feature abused for brand-impersonation phishing (confirmed 2026-07-02) ๐Ÿ”ด 16 Rate-limit/moderate free-text invitation message + logo upload for new/unverified accounts; content validation; impersonation detection TODO(owner): product/eng TODO Open ๐ŸŸก 6
R-05 Secrets/keys leaked ๐Ÿ”ด 15 Move remaining plaintext secrets (devops/cfg, frontend .env โ€” Q1 hygiene item) to a secrets manager and rotate; keep Aikido secret scanning on TODO(owner) TODO Open ๐ŸŸก 6
R-15 Backup failure / cannot restore (confirmed 2026-07-04) ๐Ÿ”ด 15 Enable PITR on both RDS instances; extend rds-soon-soon-prd retention beyond 7d; run and record first restore drill (M8); copy snapshots to isolated account/region (immutable where possible); correct customer-facing Security Overview Melvin Jacobson TODO Open ๐ŸŸข 4
R-02 No central endpoint management ๐Ÿ”ด 12 Decide: MDM tooling or documented hardening baseline + annual attestation; implement chosen option TODO(owner): Thomas proposes at sync TODO Open ๐ŸŸก 6
R-03 Credential compromise on SaaS lacking SSO/MFA (GitHub MFA on honour system, confirmed 2026-07-04) ๐Ÿ”ด 12 โšก Enable GitHub org-wide MFA enforcement setting; roll out WorkOS SSO to remaining feasible tools; maintain non-SSO list TODO(owner): GitHub org admin TODO Open ๐ŸŸข 4
R-08 Intercom US-hosted โ†’ EU-residency breach (confirmed 2026-07-03) ๐Ÿ”ด 12 Migrate to Intercom EU data hosting or replace (Linear S-303); verify remaining sub-processors; reconcile Security Overview Olaf Jacobson TODO In progress (S-303) ๐ŸŸก 6
R-09 Staging shares production RDS host ๐Ÿ”ด 12 Verify what "different state" means; confirm whether real customer data reaches staging; mask/synthesize or separate if so Thomas Picauly TODO Open ๐ŸŸข 4
R-12 Cloud misconfiguration ๐Ÿ”ด 12 IaC review in PRs; config baselines; keep Aikido cloud scanning on TODO(owner) TODO Open ๐ŸŸก 6
R-13 Unpatched dependencies/images ๐Ÿ”ด 12 Dependency scanning (Aikido) with patch SLAs (proposal: critical 7d / high 30d โ€” confirm); schedule first pentest TODO(owner) TODO Open ๐ŸŸก 6
R-14 Production outage ๐Ÿ”ด 12 Confirm/implement AWS multi-AZ; alerting via CloudWatch; write ops runbooks; draft Business/ICT Continuity Plan (A.5.29/30 gap) TODO(owner): Thomas TODO Open ๐ŸŸก 6
R-16 No formal incident response ๐Ÿ”ด 12 โšก Approve the now-written Incident Response Procedure + Breach Notification Procedure; run a tabletop exercise Olaf Jacobson TODO Partially done (documents drafted) ๐ŸŸข 4
R-19 Phishing of remote staff ๐Ÿ”ด 12 Awareness training via /isms:onboard for whole team (log in Training Log); MFA per tiered posture; reporting culture per Event Reporting Procedure Olaf Jacobson TODO Open ๐ŸŸก 6
R-22 No native product MFA for customer email/password accounts (confirmed 2026-07-03) ๐Ÿ”ด 12 Add native MFA to product roadmap with target date; interim: encourage SSO adoption for higher-risk customers; correct Security Overview Thomas Picauly TODO Open ๐ŸŸก 6
R-23 Customer data to LLM providers without confirmed DPAs (Q8) ๐Ÿ”ด 12 Map which customer data reaches OpenAI/Anthropic/Mistral/Deepseek/X.AI; obtain/verify DPAs + zero-retention/EU terms; drop non-compliant providers; update sub-processor list Thomas Picauly TODO Open ๐ŸŸก 6
R-04 Over-provisioned privileged cloud access ๐Ÿ”ด 10 โšก Run first quarterly privileged access review per Access Control Policy ยง2.4; least-privilege cleanup TODO(owner) TODO Open ๐ŸŸข 4
R-07 Customer PII breach (processor) ๐Ÿ”ด 10 Composite risk โ€” reduced by R-05/08/09/15/16 actions plus encryption and access control; verify DPA/breach-notification chain end-to-end once IR procedures approved Olaf Jacobson TODO Open ๐ŸŸก 5

3. ๐ŸŸก Medium risks โ€” decision required (treat or retain, document either way)

Risk Initial Proposed handling Decision (TODO(owner): record at sync)
R-06 Data exposure via AI tools ๐ŸŸก 9 Treat lightly: AI-use rules already in Acceptable Use Policy; confirm approved-tools list TODO
R-11 Suppliers without DPA/assessment ๐ŸŸก 9 Treat: complete supplier register + due-diligence per Supplier policy TODO
R-17 Key-person dependency ๐ŸŸก 9 Treat lightly: runbooks (with R-14), cross-training TODO
R-20 Logging/monitoring gaps ๐ŸŸก 9 Treat lightly: confirm alerting coverage per Logging & Monitoring Policy TODO
R-10 Sub-processor breach ๐ŸŸก 8 Partly shared (DPAs); monitor โ€” proposal: retain at current level TODO
R-18 Leaver access not revoked ๐ŸŸก 8 Treat lightly: adopt Termination Checklist as standard; covered by same-day revocation rule TODO

4. Roles & responsibilities

  • Risk owners (per 06-3) โ€” approve treatment for their risks and accept residual risk at management review.
  • Action owners (table above) โ€” deliver actions by the due date; attach proof.
  • Olaf Jacobson (ISM, plan owner) โ€” tracks status in the weekly sync, escalates slipping actions, brings the plan to management review.

Change log

Version Date Author Comments
0.1 โ€” โ€” CertiKit template (empty table)
0.2 2026-07-20 Andrea Cardinali Generated from Risk Assessment Report v0.4: 17 High risks with actions/owners where confirmed, 6 Medium risks pending treat/retain decision; due dates and remaining owners to be set at the 2026-07-24 sync